Skip to content

Merge pull request #83 from DanceMore/feature-macos-arm64 #79

Merge pull request #83 from DanceMore/feature-macos-arm64

Merge pull request #83 from DanceMore/feature-macos-arm64 #79

name: Security Scanners
on:
push:
branches:
- main
tags:
- '*'
paths-ignore:
- '**.md'
jobs:
scan:
runs-on: ubuntu-latest
steps:
- name: checkout code
uses: actions/checkout@v2
- name: Set up Rust
uses: actions-rs/toolchain@v1
with:
profile: minimal
toolchain: stable
- name: Build Rust project
run: cargo build --release
# - name: Install Cargo Geiger
# run: cargo install cargo-geiger
#
# - name: Run Cargo Geiger
# run: cargo geiger
- name: Perform Scan
uses: ShiftLeftSecurity/scan-action@master
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: 'ghcr.io/dancemore/dancemore/jukectl:latest'
format: 'table'
exit-code: '1'
ignore-unfixed: true
vuln-type: 'os,library'
severity: 'CRITICAL,HIGH'